Skip to content

Pin MCP package versions to avoid review drift #3308

Description

@tomelias10

The committed .mcp.json currently contains several mutable npm/npx references:

  • @upstash/context7-mcp@latest
  • @playwright/mcp@latest
  • bare @modelcontextprotocol/server-sequential-thinking

This is not evidence that any package is malicious. The issue is reproducibility / review drift: the config can stay unchanged while a future install resolves to different package code.

For deterministic review, one option is to pin reviewed exact versions and move those pins deliberately.

I verified the pattern with a passive static checker that does not execute MCP servers or download packages:
https://github.com/tomelias10/mcp-drift-check

Public config observed here:
https://github.com/commercetools/ui-kit/blob/62ca335b629de087f574af71869d68cbd3bd004c/.mcp.json

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions